diff --git a/filebeat/docs/fields.asciidoc b/filebeat/docs/fields.asciidoc index 05ac09dce9a0..92912a780cca 100644 --- a/filebeat/docs/fields.asciidoc +++ b/filebeat/docs/fields.asciidoc @@ -18,6 +18,7 @@ grouped in the following categories: * <> * <> * <> +* <> * <> * <> * <> @@ -1427,6 +1428,357 @@ Type -- +[[exported-fields-haproxy]] +== haproxy fields + +haproxy Module + + + +[float] +== haproxy fields + + + + +*`haproxy.process_name`*:: ++ +-- +Name of the process + +-- + +*`haproxy.pid`*:: ++ +-- +type: long + +Process ID + +-- + +*`haproxy.client_ip`*:: ++ +-- +client_ip is the IP address of the client which initiated the TCP connection to haproxy. + +-- + +*`haproxy.client_port`*:: ++ +-- +type: long + +client_port is the TCP port of the client which initiated the connection. + +-- + +*`haproxy.frontend_name`*:: ++ +-- +frontend_name is the name of the frontend (or listener) which received and processed the connection. + +-- + +*`haproxy.backend_name`*:: ++ +-- +backend_name is the name of the backend (or listener) which was selected to manage the connection to the server. + +-- + +*`haproxy.server_name`*:: ++ +-- +server_name is the name of the last server to which the connection was sent. + +-- + +*`haproxy.time_client_req`*:: ++ +-- +type: long + +time_client_req is the total time in milliseconds spent waiting for a full HTTP request from the client (not counting body) after the first byte was received. + +-- + +*`haproxy.time_queue`*:: ++ +-- +type: long + +time_queue is the total time in milliseconds spent waiting in the various queues. + +-- + +*`haproxy.time_backend_connect`*:: ++ +-- +type: long + +time_backend_connect is the total time in milliseconds spent waiting for the connection to establish to the final server, including retries. + +-- + +*`haproxy.time_server_response`*:: ++ +-- +type: long + +time_server_response is the total time in milliseconds spent waiting for the server to send a full HTTP response, not counting data. + +-- + +*`haproxy.time_duration`*:: ++ +-- +type: long + +time_duration is the time the request remained active in haproxy, which is the total time in milliseconds elapsed between the first byte of the request was received and the last byte of response was sent. + +-- + +*`haproxy.server_queue`*:: ++ +-- +type: long + +server_queue is the total number of requests which were processed before this one in the server queue. + +-- + +*`haproxy.backend_queue`*:: ++ +-- +type: long + +backend_queue is the total number of requests which were processed before this one in the backend's global queue. + +-- + +*`haproxy.bind_name`*:: ++ +-- + + +-- + +*`haproxy.error_message`*:: ++ +-- +type: text + +error_message is the error message logged by HAProxy in case of error. + +-- + +[float] +== geoip fields + +Contains GeoIP information gathered based on the client_ip field. Only present if the GeoIP Elasticsearch plugin is available and used. + + + +*`haproxy.geoip.continent_name`*:: ++ +-- +type: keyword + +The name of the continent. + + +-- + +*`haproxy.geoip.country_iso_code`*:: ++ +-- +type: keyword + +Country ISO code. + + +-- + +*`haproxy.geoip.location`*:: ++ +-- +type: geo_point + +The longitude and latitude. + + +-- + +*`haproxy.geoip.region_name`*:: ++ +-- +type: keyword + +The region name. + + +-- + +*`haproxy.geoip.city_name`*:: ++ +-- +type: keyword + +The city name. + + +-- + +*`haproxy.geoip.region_iso_code`*:: ++ +-- +type: keyword + +Region ISO code. + + +-- + +*`haproxy.termination_state`*:: ++ +-- +termination_state is the condition the session was in when the session ended. + +-- + +[float] +== connections fields + +Contains various counts of connections active in the process. + + +*`haproxy.connections.active`*:: ++ +-- +type: long + +active is the total number of concurrent connections on the process when the session was logged. + +-- + +*`haproxy.connections.frontend`*:: ++ +-- +type: long + +frontend is the total number of concurrent connections on the frontend when the session was logged. + +-- + +*`haproxy.connections.backend`*:: ++ +-- +type: long + +backend is the total number of concurrent connections handled by the backend when the session was logged. + +-- + +*`haproxy.connections.server`*:: ++ +-- +type: long + +server is the total number of concurrent connections still active on the server when the session was logged. + +-- + +*`haproxy.connections.retries`*:: ++ +-- +type: long + +retries is the number of connection retries experienced by this session when trying to connect to the server. + +-- + +[float] +== http fields + +Please add description + + +[float] +== response fields + +Fields related to the HTTP response + + +*`haproxy.http.response.status_code`*:: ++ +-- +type: long + +status_code is the HTTP status code returned to the client. + +-- + +*`haproxy.http.response.bytes_read`*:: ++ +-- +type: long + +bytes_read is the total number of bytes transmitted to the client when the log is emitted. + +-- + +*`haproxy.http.response.captured_cookie`*:: ++ +-- +captured_cookie is an optional "name=value" entry indicating that the client had this cookie in the response. + + +-- + +*`haproxy.http.response.captured_headers`*:: ++ +-- +type: text + +captured_response_headers is a list of headers captured in the response due to the presence of the "capture response header" statement in the frontend. + + +-- + +[float] +== request fields + +Fields related to the HTTP request + + +*`haproxy.http.request.captured_cookie`*:: ++ +-- +captured_cookie is an optional "name=value" entry indicating that the server has returned a cookie with its request. + + +-- + +*`haproxy.http.request.captured_headers`*:: ++ +-- +type: text + +captured_request_headers is a list of headers captured in the request due to the presence of the "capture request header" statement in the frontend. + + +-- + +*`haproxy.http.request.raw_request_line`*:: ++ +-- +type: text + +raw_request_line is the complete HTTP request line, including the method, request and HTTP version string. + +-- + [[exported-fields-host-processor]] == Host fields diff --git a/filebeat/docs/images/kibana-haproxy-overview.png b/filebeat/docs/images/kibana-haproxy-overview.png new file mode 100644 index 000000000000..85a24bf01f3a Binary files /dev/null and b/filebeat/docs/images/kibana-haproxy-overview.png differ diff --git a/filebeat/docs/modules/haproxy.asciidoc b/filebeat/docs/modules/haproxy.asciidoc new file mode 100644 index 000000000000..08461f50c570 --- /dev/null +++ b/filebeat/docs/modules/haproxy.asciidoc @@ -0,0 +1,62 @@ +//// +This file is generated! See scripts/docs_collector.py +//// + +[[filebeat-module-haproxy]] +:modulename: haproxy + +== haproxy module + +The +{modulename}+ module collects and parses logs from a (`haproxy`) process. + +include::../include/what-happens.asciidoc[] + +[float] +=== Compatibility + +The +{modulename}+ module was tested with logs from `haproxy` running on AWS Linux as a gateway to a cluster of microservices. + +This module is not available for Windows. + +include::../include/running-modules.asciidoc[] + +[float] +=== Example dashboard + +This module comes with a sample dashboard showing geolocation, distribution of requests between backends and frontends, +and status codes over time. For example: + +[role="screenshot"] +image::./images/kibana-haproxy-overview.png[] + +include::../include/configuring-intro.asciidoc[] + +The module is by default configured to run via syslog on port 9001. However +it can also be configured to read from a file path. See the following example. + +["source","yaml",subs="attributes"] +----- +- module: haproxy + http: + enabled: true + var.paths: ["/var/log/haproxy.log"] + var.input: "file" +----- + +:fileset_ex: http + +include::../include/config-option-intro.asciidoc[] + + +[float] +==== `http` log fileset settings + +include::../include/var-paths.asciidoc[] + + +[float] +=== Fields + +For a description of each field in the module, see the +<> section. + diff --git a/filebeat/docs/modules_list.asciidoc b/filebeat/docs/modules_list.asciidoc index 02764b903684..cab4413edbe0 100644 --- a/filebeat/docs/modules_list.asciidoc +++ b/filebeat/docs/modules_list.asciidoc @@ -6,6 +6,7 @@ This file is generated! See scripts/docs_collector.py * <> * <> * <> + * <> * <> * <> * <> @@ -27,6 +28,7 @@ include::modules-overview.asciidoc[] include::modules/apache2.asciidoc[] include::modules/auditd.asciidoc[] include::modules/elasticsearch.asciidoc[] +include::modules/haproxy.asciidoc[] include::modules/icinga.asciidoc[] include::modules/iis.asciidoc[] include::modules/kafka.asciidoc[] diff --git a/filebeat/filebeat.reference.yml b/filebeat/filebeat.reference.yml index f1265d5be43d..631a0eea5f04 100644 --- a/filebeat/filebeat.reference.yml +++ b/filebeat/filebeat.reference.yml @@ -116,6 +116,19 @@ filebeat.modules: # Filebeat will choose the paths depending on your OS. #var.paths: +#------------------------------- haproxy Module ------------------------------ +- module: haproxy + # All logs + http: + enabled: true + + # Set which input to use between syslog (default) or file. + #var.input: + + # Set custom paths for the log files. If left empty, + # Filebeat will choose the paths depending on your OS. + #var.paths: + #------------------------------- Icinga Module ------------------------------- #- module: icinga # Main logs diff --git a/filebeat/include/fields.go b/filebeat/include/fields.go index fda0f3f48415..e87e986dd908 100644 --- a/filebeat/include/fields.go +++ b/filebeat/include/fields.go @@ -31,5 +31,5 @@ func init() { // Asset returns asset data func Asset() string { - return "" + return "" } diff --git a/filebeat/module/haproxy/_meta/config.yml b/filebeat/module/haproxy/_meta/config.yml new file mode 100644 index 000000000000..5071f0fccd80 --- /dev/null +++ b/filebeat/module/haproxy/_meta/config.yml @@ -0,0 +1,11 @@ +- module: haproxy + # All logs + http: + enabled: true + + # Set which input to use between syslog (default) or file. + #var.input: + + # Set custom paths for the log files. If left empty, + # Filebeat will choose the paths depending on your OS. + #var.paths: diff --git a/filebeat/module/haproxy/_meta/docs.asciidoc b/filebeat/module/haproxy/_meta/docs.asciidoc new file mode 100644 index 000000000000..bb0111ca19c1 --- /dev/null +++ b/filebeat/module/haproxy/_meta/docs.asciidoc @@ -0,0 +1,49 @@ +:modulename: haproxy + +== haproxy module + +The +{modulename}+ module collects and parses logs from a (`haproxy`) process. + +include::../include/what-happens.asciidoc[] + +[float] +=== Compatibility + +The +{modulename}+ module was tested with logs from `haproxy` running on AWS Linux as a gateway to a cluster of microservices. + +This module is not available for Windows. + +include::../include/running-modules.asciidoc[] + +[float] +=== Example dashboard + +This module comes with a sample dashboard showing geolocation, distribution of requests between backends and frontends, +and status codes over time. For example: + +[role="screenshot"] +image::./images/kibana-haproxy-overview.png[] + +include::../include/configuring-intro.asciidoc[] + +The module is by default configured to run via syslog on port 9001. However +it can also be configured to read from a file path. See the following example. + +["source","yaml",subs="attributes"] +----- +- module: haproxy + http: + enabled: true + var.paths: ["/var/log/haproxy.log"] + var.input: "file" +----- + +:fileset_ex: http + +include::../include/config-option-intro.asciidoc[] + + +[float] +==== `http` log fileset settings + +include::../include/var-paths.asciidoc[] diff --git a/filebeat/module/haproxy/_meta/fields.yml b/filebeat/module/haproxy/_meta/fields.yml new file mode 100644 index 000000000000..88a2e576a6b7 --- /dev/null +++ b/filebeat/module/haproxy/_meta/fields.yml @@ -0,0 +1,127 @@ +- key: haproxy + title: "haproxy" + description: > + haproxy Module + fields: + - name: haproxy + type: group + description: > + fields: + - name: process_name + description: Name of the process + + - name: pid + description: Process ID + type: long + + - name: client_ip + description: client_ip is the IP address of the client which initiated the TCP connection to haproxy. + + - name: client_port + description: client_port is the TCP port of the client which initiated the connection. + type: long + + - name: frontend_name + description: frontend_name is the name of the frontend (or listener) which received and processed the connection. + + - name: backend_name + description: backend_name is the name of the backend (or listener) which was selected to manage the connection to the server. + + - name: server_name + description: server_name is the name of the last server to which the connection was sent. + + - name: time_client_req + description: time_client_req is the total time in milliseconds spent waiting for a full HTTP request from the client (not counting body) after the first byte was received. + type: long + + - name: time_queue + description: time_queue is the total time in milliseconds spent waiting in the various queues. + type: long + + - name: time_backend_connect + description: time_backend_connect is the total time in milliseconds spent waiting for the connection to establish to the final server, including retries. + type: long + + - name: time_server_response + description: time_server_response is the total time in milliseconds spent waiting for the server to send a full HTTP response, not counting data. + type: long + + - name: time_duration + description: time_duration is the time the request remained active in haproxy, which is the total time in milliseconds elapsed between the first byte of the request was received and the last byte of response was sent. + type: long + + - name: server_queue + description: server_queue is the total number of requests which were processed before this one in the server queue. + type: long + + - name: backend_queue + description: backend_queue is the total number of requests which were processed before this one in the backend's global queue. + type: long + + - name: bind_name + description: > + + - name: error_message + description: error_message is the error message logged by HAProxy in case of error. + type: text + + - name: geoip + type: group + description: > + Contains GeoIP information gathered based on the client_ip field. + Only present if the GeoIP Elasticsearch plugin is available and + used. + fields: + - name: continent_name + type: keyword + description: > + The name of the continent. + - name: country_iso_code + type: keyword + description: > + Country ISO code. + - name: location + type: geo_point + description: > + The longitude and latitude. + - name: region_name + type: keyword + description: > + The region name. + - name: city_name + type: keyword + description: > + The city name. + - name: region_iso_code + type: keyword + description: > + Region ISO code. + + - name: termination_state + description: termination_state is the condition the session was in when the session ended. + + - name: connections + description: Contains various counts of connections active in the process. + type: group + fields: + - name: active + description: active is the total number of concurrent connections on the process when the session was logged. + type: long + + - name: frontend + description: frontend is the total number of concurrent connections on the frontend when the session was logged. + type: long + + - name: backend + description: backend is the total number of concurrent connections handled by the backend when the session was logged. + type: long + + - name: server + description: server is the total number of concurrent connections still active on the server when the session was logged. + type: long + + - name: retries + description: retries is the number of connection retries experienced by this session when trying to connect to the server. + type: long + + diff --git a/filebeat/module/haproxy/_meta/kibana/default/dashboard/Filebeat-haproxy-overview.json b/filebeat/module/haproxy/_meta/kibana/default/dashboard/Filebeat-haproxy-overview.json new file mode 100644 index 000000000000..9ea04c9018b0 --- /dev/null +++ b/filebeat/module/haproxy/_meta/kibana/default/dashboard/Filebeat-haproxy-overview.json @@ -0,0 +1,406 @@ +{ + "objects": [ + { + "attributes": { + "description": "", + "kibanaSavedObjectMeta": { + "searchSourceJSON": { + "filter": [], + "index": "filebeat-*", + "query": { + "language": "lucene", + "query": "" + } + } + }, + "title": "Backend breakdown [Filebeat HAProxy]", + "uiStateJSON": {}, + "version": 1, + "visState": { + "aggs": [ + { + "enabled": true, + "id": "1", + "params": {}, + "schema": "metric", + "type": "count" + }, + { + "enabled": true, + "id": "2", + "params": { + "field": "haproxy.backend_name", + "missingBucket": false, + "missingBucketLabel": "Missing", + "order": "desc", + "orderBy": "1", + "otherBucket": false, + "otherBucketLabel": "Other", + "size": 5 + }, + "schema": "segment", + "type": "terms" + } + ], + "params": { + "addLegend": true, + "addTooltip": true, + "isDonut": true, + "labels": { + "last_level": true, + "show": false, + "truncate": 100, + "values": true + }, + "legendPosition": "right", + "type": "pie" + }, + "title": "Backend breakdown [Filebeat HAProxy]", + "type": "pie" + } + }, + "id": "55251360-aa32-11e8-9c06-877f0445e3e0", + "type": "visualization", + "updated_at": "2018-08-27T19:50:02.901Z", + "version": 2 + }, + { + "attributes": { + "description": "", + "kibanaSavedObjectMeta": { + "searchSourceJSON": { + "filter": [], + "index": "filebeat-*", + "query": { + "language": "lucene", + "query": "" + } + } + }, + "title": "Frontend breakdown [Filebeat HAProxy]", + "uiStateJSON": {}, + "version": 1, + "visState": { + "aggs": [ + { + "enabled": true, + "id": "1", + "params": {}, + "schema": "metric", + "type": "count" + }, + { + "enabled": true, + "id": "2", + "params": { + "field": "haproxy.frontend_name", + "missingBucket": false, + "missingBucketLabel": "Missing", + "order": "desc", + "orderBy": "1", + "otherBucket": false, + "otherBucketLabel": "Other", + "size": 5 + }, + "schema": "segment", + "type": "terms" + } + ], + "params": { + "addLegend": true, + "addTooltip": true, + "isDonut": true, + "labels": { + "last_level": true, + "show": false, + "truncate": 100, + "values": true + }, + "legendPosition": "right", + "type": "pie" + }, + "title": "Frontend breakdown [Filebeat HAProxy]", + "type": "pie" + } + }, + "id": "7fb671f0-aa32-11e8-9c06-877f0445e3e0", + "type": "visualization", + "updated_at": "2018-08-27T19:50:50.255Z", + "version": 1 + }, + { + "attributes": { + "description": "", + "kibanaSavedObjectMeta": { + "searchSourceJSON": { + "filter": [], + "index": "filebeat-*", + "query": { + "language": "lucene", + "query": "" + } + } + }, + "title": "IP Geohashes [Filebeat HAProxy]", + "uiStateJSON": { + "mapCenter": [ + -9.275622176792098, + 28.4765625 + ], + "mapZoom": 2 + }, + "version": 1, + "visState": { + "aggs": [ + { + "enabled": true, + "id": "1", + "params": { + "field": "haproxy.client_ip" + }, + "schema": "metric", + "type": "cardinality" + }, + { + "enabled": true, + "id": "2", + "params": { + "autoPrecision": true, + "field": "haproxy.geoip.location", + "isFilteredByCollar": true, + "precision": 2, + "useGeocentroid": true + }, + "schema": "segment", + "type": "geohash_grid" + } + ], + "params": { + "addTooltip": true, + "heatClusterSize": 1.5, + "isDesaturated": true, + "legendPosition": "bottomright", + "mapCenter": [ + 0, + 0 + ], + "mapType": "Scaled Circle Markers", + "mapZoom": 2, + "wms": { + "baseLayersAreLoaded": { + "_c": [], + "_d": true, + "_h": 0, + "_n": false, + "_s": 1, + "_v": true + }, + "enabled": false, + "options": { + "format": "image/png", + "transparent": true + }, + "selectedTmsLayer": { + "attribution": "\u003cp\u003e\u0026#169; \u003ca href=\"http://www.openstreetmap.org/copyright\"\u003eOpenStreetMap\u003c/a\u003e contributors | \u003ca href=\"https://www.elastic.co/elastic-maps-service\"\u003eElastic Maps Service\u003c/a\u003e\u003c/p\u003e\u0026#10;", + "id": "road_map", + "maxZoom": 18, + "minZoom": 0, + "subdomains": [], + "url": "https://tiles.maps.elastic.co/v2/default/{z}/{x}/{y}.png?elastic_tile_service_tos=agree\u0026my_app_name=kibana\u0026my_app_version=6.3.2\u0026license=222b9c80-1528-4ddf-9a40-cc59d57f55bf" + }, + "tmsLayers": [ + { + "attribution": "\u003cp\u003e\u0026#169; \u003ca href=\"http://www.openstreetmap.org/copyright\"\u003eOpenStreetMap\u003c/a\u003e contributors | \u003ca href=\"https://www.elastic.co/elastic-maps-service\"\u003eElastic Maps Service\u003c/a\u003e\u003c/p\u003e\u0026#10;", + "id": "road_map", + "maxZoom": 18, + "minZoom": 0, + "subdomains": [], + "url": "https://tiles.maps.elastic.co/v2/default/{z}/{x}/{y}.png?elastic_tile_service_tos=agree\u0026my_app_name=kibana\u0026my_app_version=6.3.2\u0026license=222b9c80-1528-4ddf-9a40-cc59d57f55bf" + } + ] + } + }, + "title": "IP Geohashes [Filebeat HAProxy]", + "type": "tile_map" + } + }, + "id": "11f8b9c0-aa32-11e8-9c06-877f0445e3e0", + "type": "visualization", + "updated_at": "2018-08-27T19:49:15.098Z", + "version": 2 + }, + { + "attributes": { + "description": "", + "kibanaSavedObjectMeta": { + "searchSourceJSON": { + "filter": [], + "index": "filebeat-*", + "query": { + "language": "lucene", + "query": "" + } + } + }, + "title": "Response codes over time [Filebeat HAProxy]", + "uiStateJSON": { + "vis": { + "colors": { + "200": "#508642", + "204": "#629E51", + "302": "#6ED0E0", + "404": "#EAB839", + "503": "#705DA0" + } + } + }, + "version": 1, + "visState": { + "aggs": [ + { + "enabled": true, + "id": "1", + "params": {}, + "schema": "metric", + "type": "count" + }, + { + "enabled": true, + "id": "2", + "params": { + "customInterval": "2h", + "extended_bounds": {}, + "field": "@timestamp", + "interval": "auto", + "min_doc_count": 1 + }, + "schema": "segment", + "type": "date_histogram" + }, + { + "enabled": true, + "id": "3", + "params": { + "field": "haproxy.http.response.status_code", + "missingBucket": false, + "missingBucketLabel": "Missing", + "order": "desc", + "orderBy": "_term", + "otherBucket": false, + "otherBucketLabel": "Other", + "size": 5 + }, + "schema": "group", + "type": "terms" + } + ], + "params": { + "addLegend": true, + "addTimeMarker": false, + "addTooltip": true, + "categoryAxes": [ + { + "id": "CategoryAxis-1", + "labels": { + "show": true, + "truncate": 100 + }, + "position": "bottom", + "scale": { + "type": "linear" + }, + "show": true, + "style": {}, + "title": {}, + "type": "category" + } + ], + "grid": { + "categoryLines": false, + "style": { + "color": "#eee" + } + }, + "legendPosition": "right", + "seriesParams": [ + { + "data": { + "id": "1", + "label": "Count" + }, + "drawLinesBetweenPoints": true, + "mode": "stacked", + "show": "true", + "showCircles": true, + "type": "histogram", + "valueAxis": "ValueAxis-1" + } + ], + "times": [], + "type": "histogram", + "valueAxes": [ + { + "id": "ValueAxis-1", + "labels": { + "filter": false, + "rotate": 0, + "show": true, + "truncate": 100 + }, + "name": "LeftAxis-1", + "position": "left", + "scale": { + "mode": "normal", + "type": "linear" + }, + "show": true, + "style": {}, + "title": { + "text": "Count" + }, + "type": "value" + } + ] + }, + "title": "Response codes over time [Filebeat HAProxy]", + "type": "histogram" + } + }, + "id": "68af8ef0-aa33-11e8-9c06-877f0445e3e0", + "type": "visualization", + "updated_at": "2018-08-27T19:57:55.070Z", + "version": 2 + }, + { + "attributes": { + "description": "", + "hits": 0, + "kibanaSavedObjectMeta": { + "searchSourceJSON": { + "filter": [], + "highlightAll": true, + "query": { + "language": "lucene", + "query": "" + }, + "version": true + } + }, + "optionsJSON": { + "darkTheme": false, + "hidePanelTitles": false, + "useMargins": true + }, + "panelsJSON": null, + "timeRestore": false, + "title": "[Filebeat HAProxy] Overview", + "version": 1 + }, + "id": "3560d580-aa34-11e8-9c06-877f0445e3e0", + "type": "dashboard", + "updated_at": "2018-08-27T20:03:04.536Z", + "version": 1 + } + ], + "version": "6.3.2" +} \ No newline at end of file diff --git a/filebeat/module/haproxy/http/_meta/fields.yml b/filebeat/module/haproxy/http/_meta/fields.yml new file mode 100644 index 000000000000..630075299b43 --- /dev/null +++ b/filebeat/module/haproxy/http/_meta/fields.yml @@ -0,0 +1,44 @@ +- name: http + description: Please add description + type: group + fields: + - name: response + description: Fields related to the HTTP response + type: group + fields: + - name: status_code + description: status_code is the HTTP status code returned to the client. + type: long + + - name: bytes_read + description: bytes_read is the total number of bytes transmitted to the client when the log is emitted. + type: long + + - name: captured_cookie + description: > + captured_cookie is an optional "name=value" entry indicating that the client had this cookie in the response. + + - name: captured_headers + description: > + captured_response_headers is a list of headers captured in the response due to the presence of the "capture response header" statement in the frontend. + type: text + + - name: request + description: Fields related to the HTTP request + type: group + fields: + - name: captured_cookie + description: > + captured_cookie is an optional "name=value" entry indicating that the server has returned a cookie with its request. + + - name: captured_headers + description: > + captured_request_headers is a list of headers captured in the request due to the presence of the "capture request header" statement in the frontend. + type: text + + - name: raw_request_line + description: raw_request_line is the complete HTTP request line, including the method, request and HTTP version string. + type: text + + + diff --git a/filebeat/module/haproxy/http/config/file.yml b/filebeat/module/haproxy/http/config/file.yml new file mode 100644 index 000000000000..0afd17317d4f --- /dev/null +++ b/filebeat/module/haproxy/http/config/file.yml @@ -0,0 +1,6 @@ +type: log +paths: +{{ range $i, $path := .paths }} + - {{$path}} +{{ end }} +exclude_files: [".gz$"] diff --git a/filebeat/module/haproxy/http/config/syslog.yml b/filebeat/module/haproxy/http/config/syslog.yml new file mode 100644 index 000000000000..c5c3fba1eee5 --- /dev/null +++ b/filebeat/module/haproxy/http/config/syslog.yml @@ -0,0 +1,3 @@ +type: syslog +protocol.udp: + host: "localhost:{{.syslog_port}}" diff --git a/filebeat/module/haproxy/http/ingest/pipeline.json b/filebeat/module/haproxy/http/ingest/pipeline.json new file mode 100644 index 000000000000..8b1807edded3 --- /dev/null +++ b/filebeat/module/haproxy/http/ingest/pipeline.json @@ -0,0 +1,52 @@ +{ + "description": "Pipeline for parsing HAProxy http logs in their default format. Requires the geoip plugin.", + "processors": [{ + "grok": { + "field": "message", + "patterns": [ + "(%{NOTSPACE:haproxy.process_name}\\[%{NUMBER:haproxy.pid:int}\\]: )?%{IP:haproxy.client_ip}:%{NUMBER:haproxy.client_port:int} \\[%{NOTSPACE:haproxy.http.request_date}\\] %{NOTSPACE:haproxy.frontend_name} %{NOTSPACE:haproxy.backend_name}/%{NOTSPACE:haproxy.server_name} %{NUMBER:haproxy.time_client_req:int}/%{NUMBER:haproxy.time_queue:int}/%{NUMBER:haproxy.time_backend_connect:int}/%{NUMBER:haproxy.time_server_response:int}/%{NUMBER:haproxy.time_duration:int} %{NUMBER:haproxy.http.response.status_code:int} %{NUMBER:haproxy.http.response.bytes_read:int} %{NOTSPACE:haproxy.http.request.captured_cookie} %{NOTSPACE:haproxy.http.response.captured_cookie} %{NOTSPACE:haproxy.termination_state} %{NUMBER:haproxy.connections.active:int}/%{NUMBER:haproxy.connections.frontend:int}/%{NUMBER:haproxy.connections.backend:int}/%{NUMBER:haproxy.connections.server:int}/%{NUMBER:haproxy.connections.retries:int} %{NUMBER:haproxy.server_queue:int}/%{NUMBER:haproxy.backend_queue:int} \\{%{DATA:haproxy.http.request.captured_headers}\\} \\{%{DATA:haproxy.http.response.captured_headers}\\} \"%{GREEDYDATA:haproxy.http.request.raw_request_line}\"", + "(%{NOTSPACE:haproxy.process_name}\\[%{NUMBER:haproxy.pid:int}\\]: )?%{IP:haproxy.client_ip}:%{NUMBER:haproxy.client_port:int} \\[%{NOTSPACE:haproxy.http.request_date}\\] %{NOTSPACE:haproxy.frontend_name}/%{NOTSPACE:haproxy.bind_name} %{GREEDYDATA:haproxy.error_message}" + ], + "ignore_missing": false + } + }, + { + "date": { + "field": "haproxy.http.request_date", + "target_field": "@timestamp", + "formats": ["dd/MMM/yyyy:HH:mm:ss.SSS"] + } + }, + { + "remove": { + "field": "haproxy.http.request_date" + } + }, + { + "geoip": { + "field": "haproxy.client_ip", + "target_field": "haproxy.geoip" + } + }, + { + "split": { + "field": "haproxy.http.request.captured_headers", + "separator": "\\|", + "ignore_failure": true + } + }, + { + "split": { + "field": "haproxy.http.response.captured_headers", + "separator": "\\|", + "ignore_failure": true + } + } + ], + "on_failure" : [{ + "set" : { + "field" : "error.message", + "value" : "{{ _ingest.on_failure_message }}" + } + }] +} diff --git a/filebeat/module/haproxy/http/manifest.yml b/filebeat/module/haproxy/http/manifest.yml new file mode 100644 index 000000000000..a50c2c3dede7 --- /dev/null +++ b/filebeat/module/haproxy/http/manifest.yml @@ -0,0 +1,13 @@ +module_version: 1.0 + +var: + - name: paths + default: + - /var/log/haproxy.log + - name: syslog_port + default: 9001 + - name: input + default: syslog + +ingest_pipeline: ingest/pipeline.json +input: config/{{.input}}.yml diff --git a/filebeat/module/haproxy/http/test/haproxy.log b/filebeat/module/haproxy/http/test/haproxy.log new file mode 100644 index 000000000000..ad3550d19c9c --- /dev/null +++ b/filebeat/module/haproxy/http/test/haproxy.log @@ -0,0 +1 @@ +Jul 30 09:03:52 localhost haproxy[32450]: 1.2.3.4:38862 [30/Jul/2018:09:03:52.726] incoming~ docs_microservice/docs 0/0/1/0/2 304 168 - - ---- 6/6/0/0/0 0/0 {docs.example.internal||} {|||} "GET /component---src-pages-index-js-4b15624544f97cf0bb8f.js HTTP/1.1" diff --git a/filebeat/module/haproxy/http/test/haproxy.log-expected.json b/filebeat/module/haproxy/http/test/haproxy.log-expected.json new file mode 100644 index 000000000000..551ac0bb3075 --- /dev/null +++ b/filebeat/module/haproxy/http/test/haproxy.log-expected.json @@ -0,0 +1,47 @@ +[ + { + "haproxy.server_name": "docs", + "haproxy.time_client_req": 0, + "haproxy.geoip.continent_name": "North America", + "haproxy.geoip.city_name": "Mukilteo", + "haproxy.geoip.country_iso_code": "US", + "haproxy.geoip.region_name": "Washington", + "haproxy.geoip.location.lon": -122.3042, + "haproxy.geoip.location.lat": 47.913, + "haproxy.termination_state": "----", + "haproxy.time_queue": 0, + "haproxy.pid": 32450, + "haproxy.client_port": 38862, + "haproxy.backend_queue": 0, + "haproxy.process_name": "haproxy", + "haproxy.backend_name": "docs_microservice", + "haproxy.http.request.raw_request_line": "GET /component---src-pages-index-js-4b15624544f97cf0bb8f.js HTTP/1.1", + "haproxy.http.request.captured_cookie": "-", + "haproxy.http.request.captured_headers": [ + "docs.example.internal" + ], + "haproxy.http.response.captured_cookie": "-", + "haproxy.http.response.captured_headers": [], + "haproxy.http.response.status_code": 304, + "haproxy.http.response.bytes_read": 168, + "haproxy.frontend_name": "incoming~", + "haproxy.time_duration": 2, + "haproxy.time_server_response": 0, + "haproxy.server_queue": 0, + "haproxy.client_ip": "1.2.3.4", + "haproxy.time_backend_connect": 1, + "haproxy.connections.server": 0, + "haproxy.connections.retries": 0, + "haproxy.connections.active": 6, + "haproxy.connections.backend": 0, + "haproxy.connections.frontend": 6, + "@timestamp": "2018-07-30T09:03:52.726Z", + "message": "Jul 30 09:03:52 localhost haproxy[32450]: 1.2.3.4:38862 [30/Jul/2018:09:03:52.726] incoming~ docs_microservice/docs 0/0/1/0/2 304 168 - - ---- 6/6/0/0/0 0/0 {docs.example.internal||} {|||} \"GET /component---src-pages-index-js-4b15624544f97cf0bb8f.js HTTP/1.1\"", + "input.type": "log", + "prospector.type": "log", + "fileset.module": "haproxy", + "fileset.name": "http", + "haproxy.geoip.region_iso_code": "US-WA", + "offset": 0 + } +] diff --git a/filebeat/module/haproxy/module.yml b/filebeat/module/haproxy/module.yml new file mode 100644 index 000000000000..c8023c7d1e22 --- /dev/null +++ b/filebeat/module/haproxy/module.yml @@ -0,0 +1,3 @@ +dashboards: +- id: Filebeat-haproxy-overview-dashboard + file: Filebeat-haproxy-overview.json diff --git a/filebeat/modules.d/haproxy.yml.disabled b/filebeat/modules.d/haproxy.yml.disabled new file mode 100644 index 000000000000..5071f0fccd80 --- /dev/null +++ b/filebeat/modules.d/haproxy.yml.disabled @@ -0,0 +1,11 @@ +- module: haproxy + # All logs + http: + enabled: true + + # Set which input to use between syslog (default) or file. + #var.input: + + # Set custom paths for the log files. If left empty, + # Filebeat will choose the paths depending on your OS. + #var.paths: